CPENT Sample Questions & Answers
Web application testing against the OWASP Top 10 carries the most weight, framed by scoping, OSINT gathering, social-engineering attempts, network probes from outside, inside, and the perimeter, wireless, IoT, and OT testing, cloud assessment, and reporting.
Launch the full CPENT simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Open-Source Intelligence (OSINT) · OSINT Collection and Analysis
A penetration tester wants to use Google Dorks to find publicly exposed PDF documents on a target website 'target-site.com' that might contain 'confidential' in the text. Which syntax is correct?
Show answer & explanation
Correct answer: C
The correct Google Dork syntax uses
site:to restrict results to the specific domain,filetype:to specify the file extension (pdf), and quotes aroundconfidentialto search for that specific string within the files. - Question 2Intermediate
Open-Source Intelligence (OSINT) · OSINT Collection and Analysis
You are performing a DNS analysis and suspect that the target's nameserver is misconfigured to allow Zone Transfers. You are using the
digcommand on a Linux system. Which command syntax would you use to attempt a full zone transfer for the domainexample.comfrom the nameserverns1.example.com?Show answer & explanation
Correct answer: A
The
AXFRquery type is used to request a full zone transfer. The syntaxdig @ -t AXFRdirects the request specifically to the authoritative nameserver. If successful, this reveals all DNS records in the zone. - Question 3Intermediate
Open-Source Intelligence (OSINT) · OSINT Collection and Analysis
A security consultant is using Shodan to identify industrial control systems exposed to the internet. They want to search for devices running the Modbus protocol on the standard port. Which search query should they use?
Show answer & explanation
Correct answer: B
Modbus typically runs on TCP port 502. The Shodan search query
port:502filters for this port, and addingmodbushelps refine the results to devices identifying with that protocol banner. - Question 4Intermediate
Social Engineering Penetration Testing · Social Engineering Techniques
During a social engineering engagement, you plan to use the Social-Engineer Toolkit (SET) to harvest credentials. You want to clone the target's corporate login page and host it on your attacking machine, then email a link to the employees. Which attack vector in SET should you select?
Show answer & explanation
Correct answer: B
This is the correct path in the SET menu. Website Attack Vectors allows web-based attacks; Credential Harvester focuses on collecting usernames/passwords; Site Cloner automatically copies the target URL's HTML to the attacker's server.
- Question 5Beginner
Social Engineering Penetration Testing · Social Engineering Techniques
A penetration tester is drafting a phishing email targeting C-level executives. The email is crafted to look like a subpoena from a federal court, urging immediate action. This specific type of social engineering attack is known as:
Show answer & explanation
Correct answer: C
Whaling is a specific form of spear-phishing that targets high-profile individuals ('big fish') like CEOs, CFOs, or other C-level executives. The content is usually tailored to legal, executive, or financial matters.
- Question 6Intermediate
Network Penetration Testing - External · External Network Assessment
You are attempting to scan a target network that is protected by an Intrusion Detection System (IDS). You want to fragment your Nmap scan packets to make it harder for the IDS to recognize the scanning signature. Which Nmap switch should you use?
Show answer & explanation
Correct answer: B
The
-fswitch in Nmap causes the requested scan (including ping scans) to use tiny fragmented IP packets. This splits the TCP header over several packets to make it harder for packet filters, intrusion detection systems, and other annoyances to detect what you are doing. - Question 7Intermediate
Network Penetration Testing - External · External Network Assessment
While conducting an external penetration test, you discover a Windows server with Port 445 open. You want to check for the MS17-010 (EternalBlue) vulnerability using Nmap's scripting engine. Which command is MOST appropriate?
Show answer & explanation
Correct answer: B
This command specifically targets port 445 and invokes the
smb-vuln-ms17-010script from the Nmap Scripting Engine (NSE) to check for the EternalBlue vulnerability. - Question 8Advanced
Network Penetration Testing - Internal · Internal Network Assessment
You are performing a penetration test on a corporate network and have obtained a foothold on a machine in the DMZ. You want to scan the internal network (192.168.10.0/24) but cannot route traffic directly from your attack machine. You decide to use ProxyChains with an SSH tunnel. Which of the following describes the correct setup?
Show answer & explanation
Correct answer: C
Dynamic Port Forwarding (
-D) creates a SOCKS proxy on the local machine (attacker) that routes traffic through the SSH connection to the remote host (DMZ). ProxyChains is then configured to point to this local SOCKS proxy port (default 9050), allowing tools to run through the tunnel. - Question 9Intermediate
Network Penetration Testing - Internal · Internal Network Assessment
During an internal assessment, you identify a Windows environment using LLMNR and NBT-NS. You decide to use Responder to capture hashes. After running Responder, you capture a NetNTLMv2 hash. Which tool and mode would you use to crack this hash?
Show answer & explanation
Correct answer: C
In Hashcat, mode 5600 is used for NetNTLMv2 hashes. Responder typically captures these when poisoning LLMNR/NBT-NS requests.
- Question 10Intermediate
Network Penetration Testing - Internal · Internal Network Assessment
You have compromised a domain user account and are now mapping the Active Directory trust relationships. You want to identify if there is a path to the Domain Admin group using a graphical interface. Which tool is BEST suited for this purpose?
Show answer & explanation
Correct answer: C
BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. It visually maps attack paths (like ACLs, group memberships, sessions) that can lead to Domain Admin privileges.
Ready for the real thing?
The full CPENT simulator has every exam-style question, timed mode, and instant scoring.